Apache Web Server Prefork MPM Denial Of Service Vulnerability
BID:8137
Info
Apache Web Server Prefork MPM Denial Of Service Vulnerability
| Bugtraq ID: | 8137 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0253 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery of this issue is credited to Saheed Akhtar. |
| Vulnerable: |
Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Apache Apache 2.0 Apache Apache 1.3.27 |
| Not Vulnerable: |
Apache Apache 2.0.47 |
Discussion
Apache Web Server Prefork MPM Denial Of Service Vulnerability
The Apache Software Foundation has reported a vulnerability in the prefork MPM (Multi-Processing Module) that could result in a temporary denial of service condition.
The Apache Software Foundation has reported a vulnerability in the prefork MPM (Multi-Processing Module) that could result in a temporary denial of service condition.
Exploit / POC
Apache Web Server Prefork MPM Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache Web Server Prefork MPM Denial Of Service Vulnerability
Solution:
This issue is addressed with the release of Apache 2.0.47. Users are advised to upgrade.
Conectiva has released advisory CLA-2003:698 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released advisory MDKSA-2003:075 to address this issue. See referenced advisory for additional details and fix information.
Red Hat has released advisory RHSA-2003:240-01 to address this issue.
HP has released advisory HPSBUX0309-278 to address this issue.
Trustix has released advisory 2003-0025 to address this issue.
Red Hat has released advisory RHSA-2003:244-07 to address this issue in their Linux Enterprise software. Relevant patches are available through the Red Hat Network. See the referenced advisory for additional details.
SGI has released an advisory (20031002-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10027) containing updated RPM packages relating to 22 different BIDS.
Patch 10027 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10027, please see the attached advisory.
Apache Apache 2.0
Apache Apache 2.0.28
Apache Apache 2.0.32
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Solution:
This issue is addressed with the release of Apache 2.0.47. Users are advised to upgrade.
Conectiva has released advisory CLA-2003:698 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released advisory MDKSA-2003:075 to address this issue. See referenced advisory for additional details and fix information.
Red Hat has released advisory RHSA-2003:240-01 to address this issue.
HP has released advisory HPSBUX0309-278 to address this issue.
Trustix has released advisory 2003-0025 to address this issue.
Red Hat has released advisory RHSA-2003:244-07 to address this issue in their Linux Enterprise software. Relevant patches are available through the Red Hat Network. See the referenced advisory for additional details.
SGI has released an advisory (20031002-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10027) containing updated RPM packages relating to 22 different BIDS.
Patch 10027 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10027, please see the attached advisory.
Apache Apache 2.0
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.28
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.32
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.35
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.36
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.37
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.38
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.39
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.40
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi -
Red Hat httpd-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-2.0.40-11.7.i386.rpm -
Red Hat httpd-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-2.0.40-21.5.i386.rpm -
Red Hat httpd-devel-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-devel-2.0.40-11.7.i386.r pm -
Red Hat httpd-devel-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-devel-2.0.40-21.5.i386.rpm -
Red Hat httpd-manual-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-manual-2.0.40-11.7.i386. rpm -
Red Hat httpd-manual-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-manual-2.0.40-21.5.i386.rp m -
Red Hat mod_ssl-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mod_ssl-2.0.40-11.7.i386.rpm -
Red Hat mod_ssl-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/mod_ssl-2.0.40-21.5.i386.rpm
Apache Apache 2.0.41
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.42
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.43
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.44
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.45
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi -
Conectiva apache-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_3cl. i386.rpm -
Conectiva apache-2.0.45-28790U90_3cl.src.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/SRPMS/apache-2.0.45-28790U90_3cl .src.rpm -
Conectiva apache-devel-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_3cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 3cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_3cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_3cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_3cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_3cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_3cl.i386.rpm
Apache Apache 2.0.46
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi -
Trustix apache-2.0.47-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/2.0/RPMS/apache-2.0.47-2tr.i 586.rpm -
Trustix apache-devel-2.0.47-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/2.0/RPMS/apache-devel-2.0.47 -2tr.i586.rpm -
Trustix apache-manual-2.0.47-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/2.0/RPMS/apache-manual-2.0.4 7-2tr.i586.rpm
References
Apache Web Server Prefork MPM Denial Of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Apache httpd Release 2.0 Changes (Apache Software Foundation)
- RHSA-2003-244 (Red Hat)